5.5

CVSS4.0

CVE-2025-53012 - MaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, nested imports of MaterialX files can lead to a crash via stack memory exhaustion, due to the lack of a limit on the "import chain" depth. When parsing …

📅 Published: Aug. 1, 2025, 6 p.m. 🔄 Last Modified: Aug. 1, 2025, 7:04 p.m.

3.7

CVSS3.1

CVE-2025-6011 - Timing Side-Channel in Vault’s Userpass Auth Method

A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1…

📅 Published: Aug. 1, 2025, 6 p.m. 🔄 Last Modified: Aug. 1, 2025, 7:06 p.m.

2

CVSS4.0

CVE-2025-53011 - MaterialX is Vulnerable to NULL Pointer Dereference due to Unchecked implGraphOutput

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted…

📅 Published: Aug. 1, 2025, 5:58 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:16 p.m.

2

CVSS4.0

CVE-2025-53010 - MaterialX's unchecked nodeGraph->getOutput return is vulnerable to NULL Pointer Dereference

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted…

📅 Published: Aug. 1, 2025, 5:58 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:19 p.m.

5.5

CVSS4.0

CVE-2025-53009 - MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack …

📅 Published: Aug. 1, 2025, 5:57 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:22 p.m.

6.5

CVSS3.1

CVE-2025-49832 - Asterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation

Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, between 20.00.0 and 20.15.0, 20.7-cert6, 21.00.0, 22.00.0 through 22.5.0, there is a remote DoS and possible RCE condition in `asterisk/res/res_stir_shaken /verification.c` that can be…

📅 Published: Aug. 1, 2025, 5:57 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:29 p.m.

5.3

CVSS3.1

CVE-2025-6004 - Vault Userpass and LDAP User Lockout Bypass

Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

📅 Published: Aug. 1, 2025, 5:56 p.m. 🔄 Last Modified: Aug. 1, 2025, 7:11 p.m.

6.8

CVSS3.1

CVE-2025-6037 - Vault Certificate Auth Method Did Not Validate Common Name For Non-CA Certificates

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In this configuration, an attacker may be able t…

📅 Published: Aug. 1, 2025, 5:52 p.m. 🔄 Last Modified: Aug. 2, 2025, 3:55 a.m.

6.5

CVSS3.1

CVE-2025-6014 - Vault TOTP Secrets Engine Code Reuse

Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

📅 Published: Aug. 1, 2025, 5:50 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:15 p.m.

7.4

CVSS3.1

CVE-2025-2824 - IBM Operational Decision Manager HTTP open redirect

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the U…

📅 Published: Aug. 1, 2025, 5:46 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:15 p.m.
Total resulsts: 303998
Page 5 of 30,400
« previous page » next page
Filters